PatchSiren

BUFFALO INC. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH BUFFALO INC. CVE published 2026-09-28

CVE-2026-95104

A stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition. This vulnerability has a CVSS score of 8.7 and is considered HIGH severity. The CVE record and NVD entry provide limited information about the vulnerability. Defenders should assess exposure and potential for denial-of-service (DoS) condition [truncated]

HIGH BUFFALO INC. CVE published 2026-09-28

CVE-2026-86530

BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command. This vulnerability allows for potential elevation of privileges and other security consequences. Affected products and versions need verification, and timely patching and updates are required to mitigate the vu [truncated]